Vulnerabilities (CVE)

Filtered by vendor Iatek Subscribe
Filtered by product Projectapp
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4485 1 Iatek 1 Projectapp 2024-11-21 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp, (2) search_employees.asp, (3) cat.asp, and (4) links.asp; (5) projectid parameter to pmprojects.asp, (6) ret_page parameter to login.asp, and (7) skin_number parameter to default.asp.